This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Avast! Antivirus deleted svchost.exe... [Closed]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

This was an older thread I had posted a while back for help with a wave of potential virus infections. The link to that fiasco is here:
http://forums.whatthetech.com/index.php?sh…=124407&hl=

Long story short, Avast! Free Antivirus deleted two of the svchost.exe files that turned out NOT to be infected; and now vital functions of the computer have been compromised. If you read through the replies in the link above, the assistance I was asked to provide relied on me being able to connect the damaged computer to the internet, which I was not able to do, because the internet connection program it used to run would not function and crash the entire system, forcing a cold boot. I have recently obtained an ethernet cable, which when attached automatically connects the computer to the internet, so I will now be able to post from that computer with the information requested.

Please read through the original post and advise me on what you would like me to do first. Due to the unusual nature of this particular problem, I decided against running any scans in advance and posting a log for it as you usually request, in case there's something else entirely you'd rather me do.

As always, thank you in advance for any help you can offer.
Hi mediaklepto,

Is the Start button still missing?

svchost.exe, depending on it's location may or may not be an infected file.

It looks like you have Avast5 installed. You should be able to find the log from the System File Shield within the user interface. Open the interface (left click on the orange Avast icon)
  • click on Real-time Shields
  • click File System Shield
  • in the lower right hand corner you should see Show report file
  • click on it and the log should open

It looks like System Restore may have been compromised before you posted in your original topic.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield
  • Do not copy the word CODE , please note the script starts with the :
    :reg
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr /s
    :filefind
    sr.*
    svchost.*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Please post back with
  • Avast log if you can find it
  • SystemLook log
I was unable to find the requested log button on the Avast screen; attached to the post is a screenshot of what I see on the File System Shield page, as had been requested of me in the old thread, when I was not able to get online to upload the screenshot. [attachment removed: screenshot.GIF] I apologize for the poor quality; it's just a .GIF file pasted into Paint via the clipboard. In addition, below is the transcript from SystemLook.exe: SystemLook 30.07.11 by jpshortstuff Log created at 14:49 on 19/01/2013 by Family Administrator - Elevation successful ========== reg ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr] "Type"= 0x0000000002 (2) "Start"= 0x0000000000 (0) "ErrorControl"= 0x0000000001 (1) "Tag"= 0x0000000004 (4) "ImagePath"="system32\DRIVERS\sr.sys" "DisplayName"="System Restore Filter Driver" "Group"="FSFilter System Recovery" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr\Parameters] "FirstRun"= 0x0000000000 (0) "DontBackup"= 0x0000000000 (0) "MachineGuid"="{D943BACC-C405-4AD7-B9AF-994E097D0C0F}" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr\Security] "Security"=01 00 14 80 90 00 00 00 9c 00 00 00 14 00 00 00 30 00 00 00 02 00 1c 00 01 00 00 00 02 80 14 00 ff 01 0f 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 fd 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 ff 01 0f 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8d 01 02 00 01 01 00 00 00 00 00 05 0b 00 00 00 00 00 18 00 fd 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00 (REG_BINARY) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr\Enum] "0"="Root\LEGACY_SR\0000" "Count"= 0x0000000001 (1) "NextInstance"= 0x0000000001 (1) ========== filefind ========== Searching for "sr.*" C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.83\Locales\sr.dll –a—- 8728 bytes [22:31 22/08/2012] [22:28 17/08/2012] A92879E4EBB078D3D16A8750EB58816C C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.83\Locales\sr.pak –a—- 334042 bytes [22:31 22/08/2012] [21:28 17/08/2012] A434E901B2266F7C14FD56B9BAA0954B C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\Locales\sr.dll –a—- 8728 bytes [20:31 07/09/2012] [02:58 30/08/2012] 6B135E249DDD465761FD04F8173205E3 C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\Locales\sr.pak –a—- 334042 bytes [20:31 07/09/2012] [01:50 30/08/2012] A434E901B2266F7C14FD56B9BAA0954B C:\i386\SR.IN_ –a–c- 1461 bytes [03:22 04/08/2008] [12:00 14/04/2008] 71D6B6ADFB6EF6BA68338B68A15F6E5C C:\i386\SR.MO_ –a–c- 1355 bytes [03:22 04/08/2008] [12:00 14/04/2008] 63A37C2AA9FEED2AD933B3D85235133D C:\i386\SR.SY_ –a–c- 36059 bytes [03:22 04/08/2008] [12:00 14/04/2008] A4E1694B40B24743D0C0ADBBD7953975 C:\WINDOWS\inf\sr.inf –a–c- 5038 bytes [12:53 11/03/2009] [12:00 14/04/2008] C51F64A45FE82FE926113698908F7C15 C:\WINDOWS\inf\sr.PNF –a–c- 12064 bytes [21:03 11/03/2009] [21:03 11/03/2009] 6E6ACE8975B3EA3C18B2A1FF07E5F1D0 C:\WINDOWS\system32\drivers\sr.sys –a—- 73472 bytes [05:06 12/03/2009] [12:00 14/04/2008] 76BB022C2FB6902FD5BDD4F78FC13A5D C:\WINDOWS\system32\wbem\sr.mof –a–c- 3799 bytes [12:53 11/03/2009] [12:00 14/04/2008] 010ED42FE2EE754B65FA8FC1DE7B67E1 Searching for "svchost.*" C:\i386\SVCHOST.EX_ –a–c- 7276 bytes [03:22 04/08/2008] [12:00 14/04/2008] D54450099E0666AAE89D76BD248AF6CC C:\Program Files\CheckPoint\ZAForceField\Heuristics\svchost.exe –a—- 90624 bytes [13:17 01/07/2008] [13:17 01/07/2008] FBB39A4487E11F64DCFFD36AEC2D2216 C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe –a—- 217672 bytes [17:03 07/01/2012] [17:46 03/07/2012] 8A7F34F0BBD076EC3815680A7309114F C:\WINDOWS\ERDNT\cache\svchost.exe –a–c- 14336 bytes [22:10 19/06/2010] [12:00 14/04/2008] 27C6D03BCDB8CFEB96B716F3D8BE3E18 C:\WINDOWS\Prefetch\SVCHOST.EXE-2D5FBD18.pf –a—- 23326 bytes [21:51 22/09/2012] [15:51 26/09/2012] 02EC600D209D35280BECA7EEB90FD5E8 C:\WINDOWS\system32\svchost.exe –a—- 14336 bytes [12:53 11/03/2009] [12:00 14/04/2008] 27C6D03BCDB8CFEB96B716F3D8BE3E18 -= EOF =-
Hi mediaklepto,

Your version of Avast may be slightly different than mine. In response to user input Avast sometimes moves things to make it more user freindly.

Please right click on the Avast icon and click About Avast. You should be able to see exactly what version of Avast you have. Please post that information and we should be able to locate the log if one was created.

Good news is svchost is in the correct location and system restore is intact. Not sure why OTL reported a file missing.

Is the start button still missing?

Please tell me what sysmptoms or problems you are experiencing.
Sorry, I got on the other computer - the one that actually WORKS - so I don't have the exact version of Avast! from the computer in question. However, the one I'm using currently is the exact same type of machine, an Acer AspireOne Netbook, and it's only one or two Avast! updates ahead of the troubled computer, and this is on Avast version 7.0.1474. OTL isn't the only one that tells me that computer is missing files; Avast! actually popped up and informed me it deleted two instances with the filename "svchost.exe". I confirmed that by checking Task Manager; there are usually 7 instances running; there were only 5 after Avast! deleted them. Now that those two files are gone, several programs act up or don't load at all. When the computer first turns on, no start bar loads. No task tray icons, start button, or blue bar at the bottom of the screen at ALL. Before I plugged it in with the ethernet cable so it could access the internet, the program it used to connect wirelessly, LinkSys EasyLink Advisor, would not even open, throwing an error code. Once the computer starts up and the desktop icons load, two or three messages pop up warning me about things like Skype is unable to start due to missing coding, or some such. Next time I load the bad computer up I'll get the exact text from those messages, if that helps. Other symptoms include the inability to load the Search function in Windows Explorer to look for files/folders. You click, the cutesy Windows Dog pops up, but no options to search appear, and the window is blank. There are various other flaws/malfunctions with other programs, but none immediately spring to mind like these have. Hopefully this information is of some use to you!
Hi mediaklepto,

svchost is a generic process used by various programs. It's not unusual to have a different number of instances running. It's possible that one of programs not starting may account for the missing ones. Once we get windows working properly they should come back.

Let's see if we can get some of these things sorted out.

Does the taskbar/start button ever appear or does it remain missing?

The blank search field may just be an unregistered file issue. This is usually easily fixed. Before we attempt to fix this please check and see if these areas are also blank.
  • User Accounts
  • Windows Update
  • Help and Support

This is what I see with the same version of Avast as you say you have.
📎Capture.PNG

C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)

OTL suggests it's a version of Avast5 installed on the sick computer. Is it possible to check the ill computer to confirm the version?

We'll look at the wireless connection later.
Shoot, so sorry about not replying, got busy with work this week…I'll probably post from the other computer tomorrow or the next day.
Okay, sorry about that. The Avast!version this uses is 7.0.1466. No, the start bar and button NEVER appear. I was unable to locate User Accounts and Windows Update to check for them, but Help and Support was on the dropdown menu in Windows Explorer; however clicking it caused no window to load, even after a good five minutes that I waited for it. In addition, I wrote down the two messages that pop up every single time I start this comp up. The first is the generic "encountered a problem and needs to close, send an error report" dialog; and the program that closes is "Event Monitor User Notification Tool". The second box is titled "Application Error", and reads "Exception EOleSysError in module Skype.exe at 0014215D. The RPC server is unavailable." Hopefully some of this has been useful!
Hi mediaklepto,

Let's start with this and see how we make out.

Press control, alt, delete keys at the same time to open taskmanager.

In taskmanager
  • click file
  • click new task (run)
  • Copy and paste each line into the run box , one at a time. Hit enter after each one

    regsvr32 jscript.dll
    regsvr32 vbscript.dll
You should recieve a message if it was successful or not.

Let me know if Search or Help and Support is still blank
Hi mediaklepto,

Did you restart the computer afterwards? Sometimes the fix isn't immediate.

Try this for the missing start button/taskbar.

Go to HERE to run a MS fix.

Scroll down to Fix it for me section. You should see a FixIt button. Click it to run the fix.(If you do not see the button click the + sign beside Fix it for me).
I ran the Fix it For Me, it started to install, and them I was met with this: "The Windows Installer Service could not be accessed. This can occur if you are running Windows in safe mode, or if the Windows Installer is not correctly installed. Contact your support personnel for assistance." The only thing I know for sure is; I'm not currently running in safe mode. :(
Hi mediaklepto,

Let's see if we can get a better look at this.

If you still have OTL on the computer no need to download a new copy. If you need a copy you can get it from HERE

  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Standard Output
  • In the Extra Registry section changee it to All
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Option /s
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot /s
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment|SAFEBOOT_OPTION /rs
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    consrv.dll
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
Once again, sorry for the late reply…

I ran the scan as instructed; only OTL.txt was created when it finished running. I'll post that here; if I find Extras.txt, I'll add that in a second post.

Results from OTL.txt:




OTL logfile created on: 2/11/2013 2:27:21 PM - Run 2
OTL by OldTimer - Version 3.2.65.1 Folder = C:\Documents and Settings\Family\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1013.88 Mb Total Physical Memory | 612.58 Mb Available Physical Memory | 60.42% Memory free
2.39 Gb Paging File | 2.07 Gb Available in Paging File | 86.79% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 142.05 Gb Total Space | 109.65 Gb Free Space | 77.19% Space Free | Partition Type: NTFS

Computer Name: SHUSTERSWEENEY | User Name: Family | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/09/22 16:56:46 | 000,600,576 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Family\My Documents\Downloads\OTL.exe
PRC - [2012/09/08 09:19:28 | 000,161,768 | —- | M] (Oracle Corporation) – C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2012/09/08 09:19:26 | 000,174,056 | —- | M] (Oracle Corporation) – C:\Program Files\Java\jre7\bin\javaw.exe
PRC - [2012/09/08 09:19:25 | 000,174,056 | —- | M] (Oracle Corporation) – C:\WINDOWS\system32\java.exe
PRC - [2012/07/14 08:59:32 | 000,497,320 | —- | M] (Check Point Software Technologies) – C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe
PRC - [2012/07/03 08:04:58 | 000,507,312 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Common Files\Java\Java Update\jucheck.exe
PRC - [2009/02/05 10:14:56 | 000,237,568 | —- | M] (Acer Incorporated) – C:\Program Files\Acer\Acer VCM\RS_Service.exe
PRC - [2008/12/30 02:09:54 | 000,875,016 | —- | M] (Dritek System Inc.) – C:\Program Files\Launch Manager\LManager.exe
PRC - [2008/11/13 14:43:49 | 000,204,800 | —- | M] () – C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
PRC - [2008/11/13 10:09:44 | 000,065,536 | —- | M] (Prolific) – C:\Program Files\Prolific\EZ-DUB Finder\OneBtn.exe
PRC - [2008/10/14 13:15:08 | 000,032,768 | —- | M] () – C:\WINDOWS\WebCam\M3000\M3000Mnt.exe
PRC - [2008/10/02 22:18:36 | 000,294,544 | —- | M] (Carbonite, Inc.) – C:\Program Files\Carbonite\CarbonitePreinstaller.exe
PRC - [2008/07/10 08:23:26 | 002,049,320 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero8\InCD\NBHGui.exe
PRC - [2008/07/10 08:23:26 | 000,053,032 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe
PRC - [2008/07/10 08:23:16 | 001,442,088 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe
PRC - [2008/07/10 08:23:04 | 001,083,176 | —- | M] (Nero AG) – C:\Program Files\Nero\Nero8\InCD\InCD.exe
PRC - [2008/04/15 19:54:42 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/04/14 07:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2007/09/13 20:50:00 | 001,603,152 | —- | M] (CANON INC.) – C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2007/04/13 10:49:00 | 000,101,528 | —- | M] () – C:\Program Files\Canon\IJPLM\ijplmsvc.exe
PRC - [2006/01/25 05:45:50 | 000,053,248 | —- | M] (Realtek Semiconductor Corp.) – C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe


========== Modules (No Company Name) ==========

MOD - [2008/11/13 14:43:49 | 000,204,800 | —- | M] () – C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
MOD - [2008/11/13 14:43:49 | 000,081,920 | —- | M] () – C:\Program Files\Linksys\Linksys Updater\lib\wrapper.dll
MOD - [2008/10/14 13:15:08 | 000,032,768 | —- | M] () – C:\WINDOWS\WebCam\M3000\M3000Mnt.exe
MOD - [2007/04/13 10:49:00 | 000,101,528 | —- | M] () – C:\Program Files\Canon\IJPLM\ijplmsvc.exe
MOD - [2003/06/07 00:30:08 | 000,057,344 | —- | M] () – C:\Program Files\Launch Manager\PowerUtl.dll


========== Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] – %SystemRoot%\System32\appmgmts.dll – (AppMgmt)
SRV - File not found [Auto | Stopped] – C:\DOCUME~1\Family\LOCALS~1\Temp\004659~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini – (0046591276984199mcinstcleanup)
SRV - [2012/10/05 10:08:42 | 000,109,064 | —- | M] (Wajam) [Auto | Stopped] – C:\Program Files\Wajam\Updater\WajamUpdater.exe – (WajamUpdater)
SRV - [2012/09/08 09:19:28 | 000,161,768 | —- | M] (Oracle Corporation) [Auto | Running] – C:\Program Files\Java\jre7\bin\jqs.exe – (JavaQuickStarterService)
SRV - [2012/08/21 04:12:25 | 000,044,808 | —- | M] (AVAST Software) [Auto | Stopped] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Antivirus)
SRV - [2012/07/30 11:31:04 | 002,445,880 | —- | M] (Check Point Software Technologies LTD) [Auto | Stopped] – C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe – (vsmon)
SRV - [2012/07/14 08:59:32 | 000,497,320 | —- | M] (Check Point Software Technologies) [Auto | Running] – C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe – (IswSvc)
SRV - [2012/06/05 14:17:44 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2010/03/21 14:41:00 | 003,532,120 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\WINDOWS\system32\GameMon.des – (npggsvc)
SRV - [2009/02/05 10:14:56 | 000,237,568 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Acer\Acer VCM\RS_Service.exe – (RS_Service)
SRV - [2008/12/12 18:06:40 | 000,642,856 | —- | M] (Cisco Systems, Inc.) [Auto | Stopped] – C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe – (nmservice)
SRV - [2008/11/13 14:43:49 | 000,204,800 | —- | M] () [Auto | Running] – C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe – (LinksysUpdater)
SRV - [2008/07/10 08:23:26 | 000,053,032 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files\Nero\Nero8\InCD\NBHRegInCDSrv.exe – (NeroRegInCDSrv)
SRV - [2008/07/10 08:23:16 | 001,442,088 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files\Nero\Nero8\InCD\InCDsrv.exe – (InCDsrv)
SRV - [2008/04/15 19:54:42 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON)
SRV - [2007/04/13 10:49:00 | 000,101,528 | —- | M] () [Auto | Running] – C:\Program Files\Canon\IJPLM\ijplmsvc.exe – (IJPLMSVC)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – – (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\Rts5161ccid.sys – (USBCCID)
DRV - File not found [Kernel | System | Stopped] – C:\Program Files\SUPERAntiSpyware\SABKUTIL.sys – (SABKUTIL)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\Rts516xIR.sys – (Rts516xIR)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] – – (PDCOMP)
DRV - File not found [Kernel | System | Stopped] – – (PCIDump)
DRV - File not found [Kernel | System | Stopped] – – (lbrtfdc)
DRV - File not found [Kernel | On_Demand | Stopped] – c:\acernb\int15.sys – (int15.sys)
DRV - File not found [Kernel | System | Stopped] – – (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\DOCUME~1\Family\LOCALS~1\Temp\catchme.sys – (catchme)
DRV - [2012/09/27 11:59:49 | 000,040,776 | —- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\mbamswissarmy.sys – (MBAMSwissArmy)
DRV - [2012/08/21 04:13:15 | 000,729,752 | —- | M] (AVAST Software) [File_System | System | Running] – C:\WINDOWS\System32\drivers\aswSnx.sys – (aswSnx)
DRV - [2012/08/21 04:13:15 | 000,355,632 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aswSP.sys – (aswSP)
DRV - [2012/08/21 04:13:15 | 000,054,232 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aswTdi.sys – (aswTdi)
DRV - [2012/08/21 04:13:14 | 000,097,608 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\WINDOWS\System32\drivers\aswmon2.sys – (aswMon2)
DRV - [2012/08/21 04:13:14 | 000,035,928 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aswRdr.sys – (aswRdr)
DRV - [2012/08/21 04:13:13 | 000,025,256 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\WINDOWS\System32\drivers\aavmker4.sys – (Aavmker4)
DRV - [2012/08/21 04:13:13 | 000,021,256 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\WINDOWS\System32\drivers\aswFsBlk.sys – (aswFsBlk)
DRV - [2012/07/30 10:59:48 | 000,526,640 | —- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] – C:\WINDOWS\system32\vsdatant.sys – (Vsdatant)
DRV - [2012/07/14 08:59:44 | 000,027,056 | —- | M] (Check Point Software Technologies) [Kernel | Auto | Running] – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys – (ISWKL)
DRV - [2010/05/10 13:41:30 | 000,067,656 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS – (SASKUTIL)
DRV - [2010/02/17 13:25:48 | 000,012,872 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys – (SASDIFSV)
DRV - [2009/03/02 00:03:46 | 000,038,912 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\l1c51x86.sys – (L1c)
DRV - [2009/02/25 22:17:52 | 001,344,224 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\athw.sys – (AR5416)
DRV - [2009/02/24 03:49:44 | 005,032,448 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService)
DRV - [2009/02/03 01:42:30 | 000,162,816 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV - [2009/01/02 20:33:54 | 000,145,408 | —- | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\M3000KNT.sys – (M3000Srv)
DRV - [2008/12/12 18:05:20 | 000,025,264 | —- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\purendis.sys – (purendis)
DRV - [2008/12/12 18:05:18 | 000,023,984 | —- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] – C:\WINDOWS\system32\drivers\pnarp.sys – (pnarp)
DRV - [2008/11/26 18:13:00 | 000,009,984 | —- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\plturbo.sys – (PLTurbo)
DRV - [2008/08/05 07:10:12 | 001,684,736 | —- | M] (Creative) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Ambfilt.sys – (Ambfilt)
DRV - [2008/07/10 08:23:14 | 000,040,488 | —- | M] (Nero AG) [Kernel | System | Stopped] – C:\WINDOWS\system32\drivers\InCDRm.sys – (incdrm)
DRV - [2008/07/10 08:23:14 | 000,038,952 | —- | M] (Nero AG) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\InCDPass.sys – (InCDPass)
DRV - [2008/07/10 08:23:14 | 000,018,088 | —- | M] (Nero AG) [Recognizer | System | Unknown] – C:\WINDOWS\system32\drivers\InCDrec.sys – (InCDRec)
DRV - [2008/07/10 08:23:04 | 000,128,424 | —- | M] (Nero AG) [File_System | Disabled | Running] – C:\WINDOWS\system32\drivers\InCDfs.sys – (InCDfs)
DRV - [2008/05/20 15:34:56 | 000,009,728 | —- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\plturbh.sys – (PLTurbh)
DRV - [2006/11/02 08:27:36 | 000,020,112 | —- | M] (Dritek System Inc.) [Kernel | System | Running] – C:\Program Files\Launch Manager\DPortIO.sys – (DritekPortIO)
DRV - [2006/01/04 02:41:48 | 001,389,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Monfilt.sys – (Monfilt)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACAW

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/accounts/ServiceLogi…mp;ltmplcache=2
IE - HKCU\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…1I7ACAW_enUS340
IE - HKCU\..\SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E}: "URL" = http://127.0.0.1:4664/search&s;=t-kdbOg…q={searchTerms}
IE - HKCU\..\SearchScopes\{B119812D-2A38-48DC-927D-4CBF4F4773B6}: "URL" = http://search.yahoo.com/search?fr=mcafee&p;={SearchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Secure Search"
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.startup.homepage: "https://www.google.com/accounts/ServiceLogin?service=mail&passive;=true&rm;=false&continue;=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3Dhtml%26zy%3Dl&bsv;=zpwhtygjntrz&scc;=1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}:6.0.27
FF - prefs.js..extensions.enabledItems: [removed]:7.0.1466
FF - prefs.js..keyword.URL: "
http://search.yahoo.com/search?fr=mcafee&p;="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8051.1204: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Family\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Family\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2012/08/03 13:53:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2012/09/08 09:14:47 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/02 21:36:48 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/07/03 20:05:08 | 000,000,000 | —D | M]

[2009/08/18 12:02:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Family\Application Data\Mozilla\Extensions
[2012/12/17 20:43:14 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\s9xmjwn0.default\extensions
[2012/12/17 20:35:02 | 000,000,000 | —D | M] ("Shopping Sidekick Plugin") – C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\s9xmjwn0.default\extensions\[removed]
[2012/12/17 20:35:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\s9xmjwn0.default\extensions\[removed]\chrome\content\extensionCode
[2012/09/08 12:36:41 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/28 13:20:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/11/27 17:23:05 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/03/12 18:13:37 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/08/16 11:05:00 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/09/15 14:41:54 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2012/09/08 09:14:47 | 000,000,000 | —D | M] (avast! WebRep) – C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\WEBREP\FF
[2009/09/01 18:19:43 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2009/09/08 14:55:06 | 000,027,976 | —- | M] (WebEx Communications, Inc) – C:\Program Files\mozilla firefox\plugins\atgpcdec.dll
[2009/09/08 14:55:07 | 000,126,360 | —- | M] (WebEx Communications, Inc) – C:\Program Files\mozilla firefox\plugins\atgpcext.dll
[2009/09/08 15:04:04 | 000,098,712 | —- | M] (WebEx Communications, Inc) – C:\Program Files\mozilla firefox\plugins\ieatgpc.dll
[2009/09/08 14:53:14 | 000,060,824 | —- | M] (WebEx Communications, Inc) – C:\Program Files\mozilla firefox\plugins\npatgpc.dll
[2009/08/31 23:30:17 | 000,238,776 | —- | M] (Pando Networks) – C:\Program Files\mozilla firefox\plugins\npPandoWebInst.dll

========== Chrome ==========

CHR - homepage: http://www.gmail.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage: http://www.gmail.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: ActiveTouch General Plugin Container (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npatgpc.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Pando Web Installer (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: npFFApi (Enabled) = C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AT_ChuckAnderson = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\gegkoiakifeoejnjkbnnojkkdoegeofp\3\
CHR - Extension: avast! WebRep = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1466_0\
CHR - Extension: Gmail = C:\Documents and Settings\Family\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/09/26 11:17:08 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Shopping Sidekick Plugin) - {11111111-1111-1111-1111-110211181102} - C:\Program Files\Shopping Sidekick Plugin\Shopping Sidekick Plugin.dll (215 Apps)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files\Wajam\IE\priam_bho.dll (Wajam)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [CarboniteSetupLite] C:\Program Files\Carbonite\CarbonitePreinstaller.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [InCD] C:\Program Files\Nero\Nero8\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [M3000Mnt] Rundll32.exe M3000Rmv.dll ,WinMainRmv /StartStillMnt File not found
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [Prolific2571_OneButton] C:\Program Files\Prolific\EZ-DUB Finder\OneBtn.exe (Prolific)
O4 - HKLM..\Run: [SecurDisc] C:\Program Files\Nero\Nero8\InCD\NBHGui.exe (Nero AG)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} http://simcity.ea.com/play/classic/SimCityX.cab (SimCityX Control)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{60A2B8E2-6C55-4D25-87B8-FC158D9E0D39}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D78F2BA9-07B8-4E35-865C-13DD4759FA65}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Family\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Family\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/03/12 00:07:49 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
System Restore Service not available.

========== Files/Folders - Created Within 30 Days ==========

[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/02/11 14:20:47 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/02/11 14:20:42 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/02/11 14:20:33 | 1063,198,720 | -HS- | M] () – C:\hiberfil.sys
[2013/01/30 10:40:12 | 000,000,024 | —- | M] () – C:\Documents and Settings\Family\random.dat
[2013/01/30 10:38:55 | 000,000,023 | —- | M] () – C:\Documents and Settings\Family\jagexappletviewer.preferences
[2013/01/30 10:36:09 | 000,000,062 | —- | M] () – C:\Documents and Settings\Family\jagex_cl_runescape_LIVE.dat
[2013/01/19 14:48:33 | 000,139,264 | —- | M] () – C:\Documents and Settings\Family\Desktop\SystemLook.exe
[2013/01/19 14:48:00 | 000,053,826 | —- | M] () – C:\Documents and Settings\Family\Desktop\screenshot.GIF
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/01/19 14:48:39 | 000,139,264 | —- | C] () – C:\Documents and Settings\Family\Desktop\SystemLook.exe
[2013/01/19 14:47:57 | 000,053,826 | —- | C] () – C:\Documents and Settings\Family\Desktop\screenshot.GIF
[2012/09/26 10:59:28 | 000,256,000 | —- | C] () – C:\WINDOWS\PEV.exe
[2012/09/26 10:59:28 | 000,208,896 | —- | C] () – C:\WINDOWS\MBR.exe
[2012/09/26 10:59:28 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2012/09/26 10:59:28 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2012/09/26 10:59:28 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2012/07/03 19:48:56 | 000,000,067 | —- | C] () – C:\Documents and Settings\Family\jagex_cl_runescape_LIVE_BETA.dat
[2012/05/10 09:13:49 | 000,000,063 | —- | C] () – C:\Documents and Settings\Family\jagex_cl_runescape_LIVE1.dat
[2012/05/09 21:36:21 | 000,223,080 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2012/03/10 16:01:20 | 000,000,024 | —- | C] () – C:\Documents and Settings\Family\random.dat
[2012/03/08 20:33:16 | 000,016,410 | —- | C] () – C:\Documents and Settings\Family\.recently-used.xbel
[2012/02/18 09:02:19 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/10/29 15:23:40 | 000,000,062 | —- | C] () – C:\Documents and Settings\Family\jagex_cl_runescape_LIVE.dat
[2011/03/13 22:44:49 | 000,000,023 | —- | C] () – C:\Documents and Settings\Family\jagexappletviewer.preferences
[2010/03/26 19:49:07 | 000,000,000 | —- | C] () – C:\Documents and Settings\Family\jagex__preferences3.dat
[2009/12/24 01:04:41 | 000,000,022 | —- | C] () – C:\Program Files\Sims2Pack Clean Installer.ini
[2009/10/09 12:19:16 | 000,014,336 | —- | C] () – C:\Documents and Settings\Family\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/02 17:23:59 | 000,000,129 | —- | C] () – C:\Documents and Settings\Family\jagex_runescape_preferences2.dat
[2009/08/30 10:48:20 | 000,000,140 | —- | C] () – C:\Documents and Settings\Family\Application Data\default.pls
[2009/08/27 11:20:11 | 000,001,024 | —- | C] () – C:\Documents and Settings\Family\.rnd
[2009/08/14 23:55:36 | 000,000,069 | —- | C] () – C:\Documents and Settings\Family\jagex_runescape_preferences.dat

========== ZeroAccess Check ==========

[2009/03/12 00:11:17 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini

========== LOP Check ==========

[2009/03/12 01:06:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acer GameZone Console
[2010/11/25 18:06:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2009/09/08 17:23:29 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/11/09 12:21:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2011/11/13 21:43:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CheckPoint
[2010/09/20 13:51:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EA Core
[2010/09/20 13:50:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2009/03/12 01:31:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\eSobi
[2010/05/26 21:09:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LightScribe
[2009/09/08 15:53:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Linksys
[2009/08/31 23:31:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PMB Files
[2009/09/08 15:52:56 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{35ACA973-70F0-495F-9092-74A130711865}
[2009/03/12 01:32:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\Acer
[2009/03/12 01:06:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\Acer GameZone Console
[2012/08/03 13:58:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\CheckPoint
[2012/03/08 20:33:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\gtk-2.0
[2009/08/15 06:37:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\OpenOffice.org
[2012/07/03 20:05:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\Oracle
[2009/08/14 17:33:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\SulusGames
[2009/03/12 01:27:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\Super-Cow
[2010/08/25 12:30:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Family\Application Data\SystemRequirementsLab

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2009/03/12 00:07:49 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/10/27 21:58:07 | 000,000,315 | —- | M] () – C:\Boot.bak
[2010/12/21 11:34:25 | 000,000,354 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2012/09/28 08:40:17 | 000,015,301 | —- | M] () – C:\ComboFix.txt
[2009/03/12 00:07:49 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2013/02/11 14:20:33 | 1063,198,720 | -HS- | M] () – C:\hiberfil.sys
[2009/03/12 00:07:49 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/11/25 09:26:34 | 000,009,456 | —- | M] () – C:\JavaRa.log
[2009/02/18 04:26:30 | 000,002,016 | —- | M] () – C:\MOD01SET0J00P2000K.enc
[2008/08/06 20:16:21 | 000,002,488 | —- | M] () – C:\MOD01WOS02ENP20001.enc
[2009/03/12 00:07:49 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 07:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/02/11 14:20:31 | 1598,029,824 | -HS- | M] () – C:\pagefile.sys
[2009/03/12 00:57:01 | 000,001,883 | —- | M] () – C:\RHDSetup.log
[2009/06/07 04:50:19 | 000,000,190 | —- | M] () – C:\Setup.log

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/03/12 00:07:26 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/10/22 00:00:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD97.DLL
[2007/10/22 00:00:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP97.DLL
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2006/10/26 21:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/08/21 04:12:33 | 000,041,224 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2008/12/05 00:55:20 | 000,307,560 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/12/24 01:04:41 | 000,000,022 | —- | M] () – C:\Program Files\Sims2Pack Clean Installer.ini
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2009/03/11 16:02:31 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2009/03/11 16:02:31 | 001,064,960 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2009/03/11 16:02:31 | 000,901,120 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2009/03/12 00:07:50 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2009/09/08 15:52:19 | 000,001,950 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Linksys EasyLink Advisor.lnk
[2009/08/23 15:15:13 | 000,001,611 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2009/03/12 00:07:50 | 000,000,398 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2009/03/12 00:07:50 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Desktop\*.exe >
[2010/06/19 15:43:36 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Family\Desktop\ATF_Cleaner.exe
[2013/01/19 14:48:33 | 000,139,264 | —- | M] () – C:\Documents and Settings\Family\Desktop\SystemLook.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2003/09/22 16:36:46 | 000,013,448 | —- | M] () – C:\WINDOWS\M3000Twn.src

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-09-22 22:37:27

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Option /s >

< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot /s >
"AlternateShell" = cmd.exe – [2008/04/14 07:00:00 | 000,389,120 | —- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmadmin]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmboot.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmio.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmload.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmserver]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]
"" = FSFilter System Recovery
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SRService]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vga.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}]
"" = Universal Serial Bus controllers
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}]
"" = CD-ROM Drive
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
"" = DiskDrive
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}]
"" = Standard floppy disk controller
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
"" = Hdc
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
"" = Keyboard
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
"" = Mouse
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}]
"" = PCMCIA Adapters
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
"" = SCSIAdapter
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
"" = System
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}]
"" = Floppy disk drive
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
"" = Volume
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
"" = Human Interface Devices
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmadmin]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmboot.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmio.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmload.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmserver]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ip6fw.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NtLmSsp]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpcdd.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpdd.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpwd.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sr.sys]
"" = FSFilter System Recovery
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SRService]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI]
"" = Driver Group
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdpipe.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdtcp.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\termservice]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vga.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vgasave.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vsmon]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys]
"" = Driver
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WZCSVC]
"" = Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}]
"" = Universal Serial Bus controllers
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}]
"" = CD-ROM Drive
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}]
"" = DiskDrive
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}]
"" = Standard floppy disk controller
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
"" = Hdc
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
"" = Keyboard
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
"" = Mouse
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}]
"" = Net – [2008/04/14 07:00:00 | 000,042,496 | —- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}]
"" = NetClient
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}]
"" = NetService
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}]
"" = NetTrans
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}]
"" = PCMCIA Adapters
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}]
"" = SCSIAdapter
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
"" = System
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}]
"" = Floppy disk drive
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
"" = Volume
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}]
"" = Human Interface Devices

< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment|SAFEBOOT_OPTION /rs >

< MD5 for: EXPLORER.EX_ >
[2008/04/14 07:00:00 | 000,356,615 | —- | M] () MD5=D7B59A7EC9CB1429FDCEC84A22228555 – C:\i386\EXPLORER.EX_

< MD5 for: EXPLORER.EXE >
[2008/04/14 07:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ERDNT\cache\explorer.exe
[2008/04/14 07:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/29 10:42:08 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\explorer.exe

< MD5 for: EXPLORER.SC_ >
[2008/04/14 07:00:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\i386\EXPLORER.SC_

< MD5 for: EXPLORER.SCF >
[2008/04/14 07:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CH_ >
[2008/04/14 07:00:00 | 000,199,077 | —- | M] () MD5=1D662719AB9BB40BA7526B3973D3F626 – C:\i386\IEXPLORE.CH_

< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINDOWS\Help\iexplore.chm
[2008/04/14 07:00:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\ie7\iexplore.chm
[2006/09/01 11:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.EX_ >
[2008/04/14 07:00:00 | 000,037,887 | —- | M] () MD5=2B46169148FFD81CAE84572CD32BDF86 – C:\i386\IEXPLORE.EX_

< MD5 for: IEXPLORE.EXE >
[2009/06/29 02:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2009/08/27 00:18:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 – C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2009/06/29 03:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[2009/10/28 01:54:16 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[2009/12/18 08:05:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 – C:\WINDOWS\ie8\iexplore.exe
[2008/04/14 07:00:00 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINDOWS\ie7\iexplore.exe
[2009/10/28 01:54:21 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2012/07/03 12:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINDOWS\ERDNT\cache\iexplore.exe
[2009/12/18 02:00:27 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A – C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2007/08/13 21:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[2009/08/27 00:18:44 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA – C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe
[2008/04/29 10:42:08 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 21:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINDOWS\ie8\iexplore.exe.mui

< MD5 for: IEXPLORE.HL_ >
[2008/04/14 07:00:00 | 000,059,881 | —- | M] () MD5=D23388C8D5D82D4D1C3B0B6A256E3CB7 – C:\i386\IEXPLORE.HL_

< MD5 for: IEXPLORE.HLP >
[2008/04/14 07:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp

< MD5 for: WINLOGON.EX_ >
[2008/04/14 07:00:00 | 000,265,069 | —- | M] () MD5=063EF1A46C58A731F78AE5AF47070D65 – C:\i386\WINLOGON.EX_

< MD5 for: WINLOGON.EXE >
[2012/07/03 12:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 07:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/14 07:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
[2008/07/01 08:17:12 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\winlogon.exe

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI